• Updated:
  • Published:

Antifraud

In Q1 2026, 1.53% of iGaming verification attempts came back fraudulent — up 18% year-on-year, according to Sumsub. Suspicious transaction volume jumped 4.5x; average value reached €6,002.

Bonus abuse accounts for 63.8% of that fraud. European operators lose an estimated 10–20% of marketing turnover to it. When fake accounts harvest welcome offers, CPA looks healthy and NGR bleeds.

Antifraud is the integrated set of controls an operator deploys from account creation through withdrawal. This article maps threat types, lifecycle controls, and links to AML and KYC.

What is antifraud?

Antifraud covers distinct threat types that share one outcome: someone extracts value from the operator without paying for it fairly.

Threat typeWhat it looks like
Identity fraudStolen or synthetic documents bypass verification
Payment fraudUnauthorized card use, stolen credentials, dispute abuse
Bonus abuse / multi-accountingMultiple accounts harvest welcome offers and referral bonuses
Account takeover (ATO)Compromised logins drain balances or launder withdrawals
Money launderingGambling used to layer or integrate illicit funds — overlaps AML

KYC establishes identity. AML monitors financial crime and files SARs. Antifraud adds behavioural analytics and device intelligence for threats neither layer catches — bonus hunters who pass document checks, chargeback artists who are “verified,” affiliate traffic that never retains.

The scale of the problem

European Gaming cites Sumsub data: verification fraud rose from 1.10% in 2024 to 1.53% in Q1 2026. Between 2022 and 2024, iGaming fraud grew 64% by the same methodology.

Sumsub reports fraudsters now take 4.6x longer on verification than legitimate players. They make 20–30% more attempts and cluster in outlier speed groups. AI tooling industrialises bonus abuse and multi-accounting at scale.

Regional hotspots sharpen the picture. Africa posted a 2.5% fraud rate in Sumsub’s Q1 2026 data — highest of any region — with 97% of fraud caught at the selfie step and Côte d’Ivoire leading West Africa at 7.8%.

How does antifraud work?

Effective antifraud operates at every stage of the player lifecycle — not only at registration.

1. Onboarding

The registration process is the first control point. Operators run document verification, biometric liveness, database cross-referencing, and device fingerprinting to block synthetic identities before platform access. Frogo recommends blocking temporary email domains, VoIP numbers, and bot traffic via CAPTCHA alongside ID checks.

Industry experience consistently shows most fraud events happen after registration — in deposit and bonus phases — but onboarding still sets the baseline signal quality downstream.

2. Deposit screening

Every deposit earns a risk score: card ownership (AVS, 3DS), IP and geolocation, velocity limits, cross-reference against fraud intelligence pools.

Fast auto-deposit rails increase transaction velocity — screening must run in parallel. Card-not-present fraud often flags at deposit through billing address mismatch, before the fraudster reaches withdrawal.

3. Behavioural monitoring

Session analytics catch automated play, exploitative bonus-period wagering, low-variance betting engineered for predictable outcomes, and gnoming patterns where coordinated accounts hedge opposite outcomes. Sumsub tracks rings using VPNs, residential proxies, family sharing, purchased accounts, and affiliate fraud funnels.

The UK’s 10x wagering cap, effective from 19 January 2026, removes one legacy defence — making bonuses easier to clear and shifting burden to detection-first architectures.

4. Withdrawal controls

Withdrawals are the last gate before cash leaves. Operators run AML screening, confirm KYC currency, verify wagering requirements were met legitimately, and route large or atypical payouts to manual review. NOTO frames the tension plainly: slow payouts frustrate players; weak controls expose the operator to chargebacks and regulatory scrutiny.

5. Post-event review

Chargeback disputes and SAR filings close the loop. Complete audit trails — login timestamps, device IDs, IP history, gameplay logs — support representment and regulatory inspection. Operators must retain records five to seven years in most licensed jurisdictions.

Major fraud types in depth

Bonus abuse and multi-accounting

63.8% of iGaming fraud is bonus abuse. Fraudsters create multiple profiles with varied documents and shared payment methods — each claiming a welcome bonus. Rings scale through synthetic identities and mule networks European Gaming describes as gnoming.

The commercial damage spreads across teams. Marketing sees inflated acquisition metrics. Risk queues manual reviews. Payments handles suspicious withdrawals. Retention spends on accounts that were never legitimate players.

Payment fraud and chargebacks

iGaming chargeback rates run 2–4% versus 0.5–1% in standard e-commerce — two to four times higher, per industry benchmarks. 60–70% of iGaming chargebacks are “friendly fraud” — players disputing legitimate charges with their bank rather than requesting operator refunds.

The all-in cost per $100 chargeback reaches roughly $207. Visa’s VAMP programme tightens thresholds from April 2026: above 1.5% disputes triggers fines; above 1.8% risks account termination.

Account takeover

Compromised credentials let attackers drain balances or route withdrawals. Strong authentication — biometrics, step-up verification on device change — doubles as bonus abuse defence. Frogo notes measures against multi-accounting also reduce ATO surface area.

Detection toolkit

Modern stacks layer:

  • Device fingerprinting — hardware and browser attributes build a persistent device ID; European Gaming cites this as the primary multi-accounting signal
  • IP fraud scoring — VPN, proxy, and anonymous browser detection
  • Liveness and biometric IDV — catches deepfakes and presentation attacks
  • Duplicate account and fraud network detection — graph analysis on shared payment, device, and behavioural links
  • Dynamic risk scoring — re-score at first withdrawal, threshold deposit, device change, return after dormancy

Sumsub argues KYC alone leaves exposure — device, behaviour, network, and document intelligence must merge into one player risk view.

Unified risk stack vs siloed tools

NOTO describes the failure mode: bonus abuse rises, so marketing adds rules; chargebacks rise, so payments tightens; compliance expands workflows. Each fix makes sense alone. Together they create conflicting signals and duplicate queues.

The alternative is a single risk layer spanning acquisition through withdrawal — feeding AML monitoring and antifraud scoring from the same player profile.

Why antifraud matters

Revenue. Fraud erodes GGR and NGR directly. Bonus abuse consumes promotional budget without sustainable player value. Chargebacks carry per-dispute fees and can push operators above card network monitoring thresholds — elevating processing costs or terminating merchant accounts.

Regulatory. UKGC, MGA, and FATF-aligned frameworks require adequate fraud controls. Cross-border operators maintain regulator-specific controls while sharing risk signals where data law permits. Non-compliance exposes operators to licence suspension — often co-enforced with AML failures.

Acquisition quality. High fraud from a traffic source signals affiliate problems. Elevated fraud from one partner triggers scoring, CPA holdbacks, and partner audits. An affiliate driving bonus exploiters is a commercial defect, not a marketing win.

Examples

Multi-accounting ring. A coordinated group registers hundreds of accounts with slightly varied documents. Device fingerprinting, IP clustering, and shared payment method detection flags the cluster before wagering cycles complete. Promotional cost is avoided; accounts suspend with evidence preserved.

Card-not-present fraud. A fraudster funds a sportsbook with compromised card data, places bets, and attempts withdrawal before the cardholder disputes. Velocity controls and AVS failure decline the deposit; card data enters the operator’s fraud signal pool.

Scope distinction. AML targets financial crime — movement and concealment of illicit funds. Antifraud is broader: bonus abuse, multi-accounting, ATO, and payment fraud that reduce revenue without necessarily involving laundering. Both programmes share data inputs and differ in response protocols.

Common pitfalls

False positives. Blocking all VPN traffic or flagging every rapid deposit rejects genuine players. A 5% false positive rate on deposits can mean hundreds of blocked legitimate sessions monthly — direct revenue loss. Target below 1% fraud loss while maintaining high approval rates.

Point-in-time KYC. Treating verification as a one-time gate misses post-registration fraud — the highest-frequency vector.

Siloed fraud and AML. Separate stacks generate conflicting signals and duplicate reviews. Unified scoring reduces both.

Data fragmentation. Without a real-time pipeline connecting game events, payments, identity, and behaviour, risk engines operate on incomplete pictures.

Best practices

  • Risk-based tiering — friction proportional to signal strength; low-risk verified players move fast, high-risk profiles trigger step-up EDD
  • Lifecycle monitoring — re-score at withdrawal, threshold deposits, device changes, dormancy returns
  • Unify fraud and AML data — one player risk profile, two response protocols
  • Document false-positive tolerance — explicit business trade-off between fraud loss and conversion loss
  • Feed fraud data into affiliate reporting — high multi-accounting rates trigger CPA reviews and holdbacks
  • Maintain audit trails — five to seven years for chargeback representment and regulatory inspection

Bottom line

Antifraud is a continuous operational layer, not a checkbox at onboarding. Most fraud happens after registration — in deposit and bonus phases.

The best outcomes combine verification at registration with behavioural scoring, unified fraud and AML profiles, and feedback loops into acquisition and CRM.

When 63.8% of fraud chases the same promotional budget, antifraud is revenue management with a fraud desk.